Suspicious Key Manager Access

 Original Source: [Sigma source]
Title: Suspicious Key Manager Access
Status: test
Description:Detects the invocation of the Stored User Names and Passwords dialogue (Key Manager)
References:
  -https://twitter.com/NinjaParanoid/status/1516442028963659777
Author: Florian Roth (Nextron Systems)
Date: 2022-04-21
modified:2023-02-09
Tags:
  • -'attack.credential-access'
  • -'attack.t1555.004'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\rundll32.exe' OriginalFileName:'RUNDLL32.EXE'   selection_cli:
    CommandLine|contains|all:
      -'keymgr'
      -'KRShowKeyMgr'

  condition:all of selection_*
Falsepositives:
  -Administrative activity
Level: high